1. Introduction
Cloudsealed LLC respects the privacy of every visitor, client and partner who interacts with our computer integrated systems design practice. This Privacy Policy explains in plain language how we collect, use, store, share and protect personal information across this website and across the consulting engagements we run. The company also works closely with the developer named CloudSealed, and the principles on this page bind that developer every bit as firmly as they bind the company itself.
We encourage you to read this policy in full before you submit personal information through the contact form, the service request panel or any other channel we operate. By using this website or by engaging our services, you acknowledge that you have read and understood the practices described here.
Company contact details appear at the end of this policy. We welcome questions and will respond to any request for clarity within a reasonable working window.
2. Scope of this policy
This policy applies to personal information that we handle in connection with our website at cloudsealed.hair, our correspondence services, and any consulting projects performed under the banner of Cloudsealed LLC. It covers information you give to us directly, information gathered automatically as you browse, and information we receive from clients when they ask us to design an integrated system on their behalf.
The policy does not cover the practices of third party websites that we may link to, and it does not cover information handled by any service provider under its own privacy notice. Where we act only as a processor for a client of systems we have designed, that client remains the controller of your information and its own notice governs.
If part of this policy conflicts with a specific contractual requirement we have agreed with a client, the contract prevails within the boundaries the law allows.
3. Information we collect
We keep our data collection to the minimum that good design requires. The categories of personal information we may collect are set out here so you always know what we hold.
- Contact data, including your name, your professional email address, your company name and a phone number when you choose to provide one.
- Correspondence data, including the subject line and the body of any message you send through our intake forms or by direct email.
- Enquiry data, including the service bay that interests you and the details you attach to a request for enterprise integration, architecture, cloud, modernisation, pipeline or service management work.
- Technical data, including your internet protocol address, browser type, operating system, referring pages and the dates and times of your visits.
- Usage data, including which parts of the website you open and for how long, gathered through standard server logs and any analytics we activate.
- Project data, which we receive only as part of a signed consulting engagement and which may include system diagrams, configuration notes and technical specifications that you own.
- Photo or identity data only where we verify a commercial relationship and where the law or your employer requires it.
We do not deliberately collect sensitive categories such as health, biometric or political data, and we ask that you never send such information in an unsecured intake message.
4. How we collect information
Information reaches us through a small number of clearly defined doors, and we track each one so we can tell you exactly where any piece of data came from.
- Direct submission, when you complete the name, email, subject and message fields of our contact or service request forms.
- Electronic mail, when you contact serve@cloudsealed.hair directly or reply to one of our notes.
- Telephone, when you call the number printed on our panels and speak with a member of the team.
- Commercial exchange, when a prospective client shares an RFP, a statement of work or a technical annex to begin a design effort.
- Automatic collection, through server logs and similar tools that record standard technical metadata as you navigate the site.
We do not buy personal data from brokers, and we do not harvest address lists from public sources to build a marketing file. Every record we hold can be traced to a genuine interaction or a signed agreement.
5. Purpose of processing
We process personal information for defined, documented purposes and we use each piece of data only for the reason it was collected or for a purpose closely compatible with that reason.
- To respond to your requests, which means reading your intake message and replying with the correct next step for the service you need.
- To arrange and deliver consulting work, which means scheduling calls, sharing statements of work and coordinating design reviews with you.
- To bill and administer accounts, which means issuing invoices, processing payment details through approved channels and keeping our own books accurate.
- To maintain service quality, which means engineering secure systems, resolving faults and learning from how the site and our tools perform.
- To send service notices, which means informing you about work you have already asked for rather than unsolicited promotion.
- To meet legal duties, which means replying to valid legal process and keeping the records that regulations require of us.
We use website analytics in a way that does not single you out for advertising. Our focus is design reliability, honest engineering and a working relationship people can trust for years.
6. Legal bases for processing
Where data protection law requires us to name a legal basis, we rely on the following reasons depending on the situation.
- Consent, which we obtain before we place non-essential tracking or before we market to a new contact. You may withdraw consent at any time and we will honour the withdrawal promptly.
- Performance of a contract, which covers the processing needed to quote for, begin, run and close a consulting engagement you have agreed to.
- Legitimate interests, which cover the ordinary running of a professional business such as answering enquiries, fraud prevention, network security and reasonable record keeping where your rights do not outweigh those interests.
- Legal obligation, which covers situations where retention or disclosure is demanded by an applicable law, regulation or court order.
We assess each basis honestly and we document the reasoning whenever the borderline is close, so that our decision process is traceable after the fact.
7. Use of cookies
This website may use small text files, commonly called cookies, along with similar local storage that helps it remember your choices. We separate these into strictly necessary ones and optional ones.
- Strictly necessary cookies keep the site functional, for example by remembering that a form was submitted or that the correct language is already selected.
- Analytics cookies, where enabled, count visits and measure which units are read so we can improve the site without identifying individuals by name.
- Preference cookies store lightweight choices such as the fact that you visited recently so we do not repeat a notice.
We do not set advertising cookies, and we do not sell any data that cookies reveal. If you prefer, you can set your browser to refuse all cookies; the core content of this site continues to work without them. Where a law requires consent for a category of cookie, we ask before loading that category.
8. Sharing of information
Cloudsealed LLC does not sell personal information, and we do not rent it to anyone. We share information only in the limited and well-justified cases listed here, and only to the extent each case requires.
- With service providers, such as web hosting, analytics, email, accounting and payment firms that support the operation of this site and our back office, each bound by a written contract that restricts their use of the data.
- With professional advisers, including lawyers and accountants, where we reasonably need their assistance to protect our rights or meet our obligations.
- With client systems we design, but only under the terms of the contract that governs that work and only for the client that owns the system.
- With regulators or the courts, where we are validly asked to provide information by law, by legal process or by a government authority acting within its powers.
- In a business transition, such as a merger or acquisition, only with notice to you where we are permitted to give it.
Every partner we share data with performs a function we could describe precisely to you, and every arrangement restricts onward use so your information does not wander.
9. International transfers
Cloudsealed LLC operates from the United States, and our offices and primary storage are located there. Information you provide may therefore be processed in the United States even if you send it from another country.
Where personal data crosses national borders, we apply safeguards that are appropriate to the route. In practice we prefer to store client and contact data inside the United States, we choose suppliers that publish clear sub-processor lists, and we enter into the standard contractual clauses the law recognises wherever a transfer demands them.
If you send us information from the European Economic Area, the United Kingdom or Switzerland, the protections described in this policy continue to apply to that information wherever it is held, and we commit to honouring the safeguards set out in the sections that follow.
10. Data retention
We keep personal information no longer than we need it for the purpose we collected it, and we delete or anonymise it once that purpose has ended together with any legal retention period that applies.
- Enquiry data is held for a short practical period so we can respond to you and follow up on a genuine request.
- Project records tied to a signed engagement are kept for the term of the engagement plus the retention windows that tax and commercial law require.
- Accounting records are kept for the period mandated by the relevant revenue authority.
- Server and technical logs are rotated on a routine schedule so that raw logs do not lie idle for years.
- Consent records are kept only as long as the consent they evidence remains actioned and relevant.
When a retention period lapses, files are purged irrecoverably or reduced to aggregated statistics that no longer identify a living person. We would rather erase cleanly than hoard blindly.
11. Data security measures
Because we design integrated systems for a living, we hold our own data practice to the same rack-side discipline we sell to clients. Security is a set of layered controls, not a single padlock.
- We encrypt data in transit using current transport security and we protect data at rest with strong encryption where the storage medium supports it.
- We grant access on a need-to-know basis, so the smallest practical group of named engineers can reach personal information.
- We protect accounts with unique passwords, multi-factor verification where available, and prompt revocation when someone leaves the team.
- We keep software patched, we scan our own environments for obvious weakness, and we review our configuration whenever a material change is made.
- We train anyone who handles your data to treat it as a live system device, sensitive to loss and theft just like a server that holds a client estate.
No method of transmission or storage is completely risk-free, and we cannot promise absolute security. What we can promise is that we apply industry-reasonable controls and that we respond responsibly if a weakness surfaces.
12. Your rights
Depending on where you live and the law that governs our relationship, you may hold a number of rights over the personal information we keep about you. We honour these rights through the contact route at the foot of this policy.
- Right of access, so you can ask what we hold and receive a readable copy.
- Right of rectification, so you can correct information that is inaccurate or incomplete.
- Right of erasure, so you can ask us to delete information where the law permits.
- Right to object, so you can challenge processing grounded in our legitimate interests or aimed at unsolicited direct outreach.
- Right of restriction, so you can ask us to hold but not actively use information while a dispute is resolved.
- Right to portability, where applicable, so you can receive some records in a structured machine-readable form.
- Right to withdraw consent, so you can cancel permission you previously granted.
- Right to complain, so you can report your concern to the supervisory authority in your own country.
We will not penalise you for exercising a right, and we will answer a genuine request without unreasonable delay and without charge in the ordinary course.
13. Privacy for Children
Our website and our consulting services are directed at professional, scientific and technical operators, and they are not aimed at children under the age of thirteen. We do not knowingly collect personal information from children, and the intake forms on this site expect business contacts rather than minors.
If you believe a child has provided us with personal information, contact us using the details at the foot of this policy and we will take reasonable steps to remove that information from our records. Where a national law sets a higher age threshold for consent, we comply with that higher threshold in the relevant jurisdiction.
14. Third party links
This site and the project documents we share may point to websites operated by other organisations, including our suppliers, our reference customers and public bodies. Those outbound links lead to destinations whose privacy practices sit outside this policy.
When you leave our site, we no longer control what those third parties collect or how they use it. We recommend that you read the privacy notice of any site you visit before you hand over personal information there. A link is not an endorsement of the privacy stance of the destination, even when the linked partner is reputable.
15. Automated decisions
Cloudsealed LLC does not use automated decision-making, profiling or algorithmic scoring to make decisions that produce legal or similarly significant effects about you. Choosing a service bay, routing your request or scheduling a call is a human judgement exercised by a named member of our team.
Should we ever introduce automated evaluation for routing or quality in the future, we will update this policy first and we will make sure any such tool is understandable, explainable and open to human review.
16. Policy changes
We review this Privacy Policy periodically and we reserve the right to amend it when our practices or the law change. Each version carries an effective date at the top of the page so you can see at a glance how current the text is.
Material changes will be signalled on the homepage rather than buried in a link, and where we rely on your consent for a new activity we will ask for fresh consent rather than assume the old one still stands. Continued use of the site after a clearly dated revision means you accept the revised policy as of its effective date.
17. Contact information
592 W 200 S Unit 613
Salt Lake City - 84101-1228
United States (US)
Email: serve@cloudsealed.hair
Phone: +17758063997
If you write to us about this policy, mention Privacy in the subject line so the message reaches the right member of staff on the first pass. We aim to acknowledge every privacy enquiry promptly and to give you a substantive answer without unreasonable delay.
18. Governing law
This Privacy Policy and the handling of personal information under it are governed by the laws of the State of Utah, United States, without regard to its conflict of law rules. Any dispute arising in connection with this policy that cannot be resolved amicably will be subject to the exclusive jurisdiction of the courts located within the State of Utah, United States.
This governing clause does not diminish any mandatory rights you hold under the data protection law of your own country. Where one part of this policy is found unenforceable, the remaining parts continue in full force.